yagames-mcp

An MCP server for Yandex Games: catalog search with no auth, plus draft management, build uploads and publishing through the developer console

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Can publish and update games on behalf of the developer account
  • The Session_id and CSRF token grant full console access rather than scoped rights
  • Authentication relies on unofficial cookie access rather than a platform-issued key
All reasons and checks
Russian stack

petergs27/yagamesmcp

Install

Manual install

npm install
npm run build

Install dependencies and build the project.

This is third-party code. Review the repository files before installing.

What it does

The server offers two tool layers. Public tools need no authentication: searching games by keyword, listing popular games filtered by category, and listing 27 genres, all read from the yandex.ru/games catalog page. Authenticated tools work through the developer console: creating and updating a game draft, uploading a ZIP build as a new version, submitting for moderation, publishing a game that passed review, and checking status or listing every game on the account. Authentication is not an official API key but a Session_id cookie and an X-CSRF-Token header, copied manually from browser DevTools after logging into the console.

Who it is for. For HTML5 game developers who publish to the Yandex Games catalog and want to automate build uploads.

Good fit when

  • You want to quickly browse the catalog, popular games or genre list without logging in
  • You want to automate uploading a new build and submitting it for moderation from a conversation with an agent
  • You run several games on one developer account and need a unified status view

Not a fit when

  • You do not want to manually pull the Session_id and CSRF token from DevTools and store them in environment variables
  • You need an official API instead of unofficial console-cookie access: the project offers no other way

Example request

Check the moderation status of all my games on Yandex Games

Limitations

Publishing and build uploads work through unofficial developer-console cookie access rather than a documented API key. The Session_id and CSRF token grant full access to the developer account and have no built-in expiry handling in the project; the author explicitly warns not to share them. Public search is built on parsing the catalog page's HTML and can break if it changes.

How to disable. Remove the server from your MCP client config and log out of the Yandex Games console to invalidate the Session_id.

MCP

Transport
stdio
Authentication
API key
Environment variables
Environment variables
YAGAMES_SESSION_COOKIE
secret
The Session_id cookie value from the developer console, needed for game management
YAGAMES_CSRF_TOKEN
secret
The X-CSRF-Token header value from the developer console

Security check

  • Can publish and update games on behalf of the developer account
  • The Session_id and CSRF token grant full console access rather than scoped rights
  • Authentication relies on unofficial cookie access rather than a platform-issued key

README in short

The English README splits tools into public, no-auth ones and authenticated console ones. It gives a tool table, instructions for pulling the Session_id and CSRF token from DevTools with an explicit warning not to share or commit them, config examples for opencode and Claude Desktop, an architecture diagram separating the catalog client from the console client, a list of console REST endpoints, and background on the Yandex Games platform: over 2,000 games, 27 genre categories, ad-based monetization. MIT license.

FAQ

Does game search need authentication?

No, the yagames-search, yagames-popular and yagames-categories tools are public and need no keys or cookies.

Where do I get the Session_id and CSRF token?

From browser DevTools after logging into games.yandex.ru/console: the Session_id cookie under the Application tab, and the X-CSRF-Token header on a POST request to /console/api/application under the Network tab.

Editors’ pick

A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review

PluginMedium riskNo VPN needed292.5KRepository stars
Editors’ pick

Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture

SkillLow risk271.4KRepository stars
Editors’ pick

GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation

CLIMedium riskNo VPN needed139.3KRepository stars

Reference MCP servers

Model Context Protocol servers

Official

Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything

MCP serverMedium risk90.6KRepository stars
Foxx AIyagames-mcp

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.